What Is Hysteria2?
Hysteria2 is a QUIC-based proxy protocol focused on poor-network performance, using a password-authenticated UDP transport.
Последняя проверка: 28 сент. 2026 г., 05:52 · originally in EN
Overview
Hysteria2 is a proxy protocol built on QUIC, the UDP-based transport underneath HTTP/3. It was redesigned from the original Hysteria to behave like HTTP/3 as much as possible: the connection uses a standard TLS 1.3 handshake over UDP, and authentication is a simple password in the URI. Its defining feature is a brutal congestion-control mode that intentionally saturates a link instead of backing off, which helps on lossy or throttled paths where TCP-based protocols collapse.
Anatomy of a hysteria2:// link
Hysteria2 share links are deliberately simple:
- Auth string - the password, placed where a username would sit.
- Host and port - typically a UDP port such as 443.
- `sni` - the server name for the TLS handshake.
- `insecure` - skips certificate verification when set.
- `obfs` - optional Salamander obfuscation that disguises QUIC traffic.
You can decode any of these with the config parser.
Strengths and costs
Because it runs over UDP, Hysteria2 avoids TCP head-of-line blocking and recovers from packet loss quickly, often outperforming WebSocket or gRPC tunnels on bad networks. The trade-off is that some networks rate-limit or block UDP entirely, in which case a TCP-based protocol such as Trojan or VLESS may be the only option. The aggressive congestion mode can also be unfair to other traffic sharing the same link.
Limitations
insecure=1 links skip TLS verification and are vulnerable to interception; prefer verified endpoints when possible. Hysteria2 support in client apps is common but not universal - check the client directory before importing. HiddenIO indexes public sources and cannot guarantee that any Hysteria2 endpoint works or is safe to use.